Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
Via
X-Powered-By
Pragma
CF-RAY
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-Generator
X-Ua-Compatible
X-Cache-Status
X-Cacheable
X-CONTENT-TYPE-OPTIONS
Accept-Ch
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-XSS-PROTECTION
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Status
Content-Encoding
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Amz-Version-Id
X-Backend
Cf-Edge-Cache
X-Robots-Tag
Keep-Alive
X-Hacker
CONTENT-SECURITY-POLICY
Cf-Apo-Via
X-Via
X-Turbo-Charged-By
X-Request-ID
X-Vhost
X-AH-Environment
X-Server
X-Rq
X-Dispatcher
X-Cache-Group
X-Proxy-Cache
X-Ws-Request-Id
EagleId
X-Varnish-Cache
X-UA-Device
Grace
Pantheon-Trace-Id
X-Litespeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
X-FTR-Request-ID
X-Node
Ali-Swift-Global-Savetime
X-Host
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-Akam-SW-Version
Cache-Tag
X-Response-Time
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-Ua-Device
X-Content-Type
X-LiteSpeed-Cache
Content-Location
Cross-Origin-Opener-Policy
X-Nginx-Cache-Status
X-Element-Page-Cache
X-Nginx-Upstream-Cache-Status
Request-Id
X-Oneagent-Js-Injection
X-D2id
X-Rack-Cache
X-Application-Context
Service-Worker-Allowed
X-Trace
X-TraceId
Fastly-Restarts
X-Nf-Request-Id
X-Times
X-PC
X-Vname
X-TtlSet
X-Navigation-Version
Rating
X-Clacks-Overhead
X-Cnection
X-Country
X-Edge
X-Mcache
X-Midtier
X-Vcap-Request-Id
X-Browser-Type
Origin-Trial
Edge-Control
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-ESI
X-FTR-Expires
X-Cache-TTL
X-Url
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-ECACHE
X-Ac
X-Powered-By-Plesk
X-Abt-Application-Version
X-Mod-Pagespeed
X-Amz-Rid
X-Upstream
X-Request-Device-Id
Verso
X-ORACLE-DMS-RID
X-B3-TraceId
X-MS-InvokeApp
X-Language
X-Meli-Trace-Site
X-Meli-Trace-Bu
X-Meli-Trace-Platform
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Akamai-GRN
Nginx-Cache
X-Amzn-Trace-Id
X-GitHub-Request-Id
Display
X-Middleton-Display
Pagespeed
X-Sol
S
X-T
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Envoy-Decorator-Operation
X-Ruxit-Js-Agent
SPRequestGuid
X-SharePointHealthScore
SPRequestDuration
SPIisLatency
AR-PoweredBy
AR-ATIME
Response
X-Middleton-Response
AR-Request-ID
Edge-Cache-Tag
X-Distributor
X-Goog-Hash
X-Ratelimit-Limit
X-Ser
X-Resp-Is-Stale
X-Edge-Location-Klb
X-Kinsta-Cache
X-Request-Received
X-Request-Processing-Time
X-ARC
X-NGENIX-Cache
Access-Control-Request-Method
Front-End-Https
X-Shield-Request-Id
X-Dw-Request-Base-Id
Ar-SID
RTSS
X-Ezoic-Cdn
X-Cache-Key
X-Recruiting
X-Client-IP
X-Content-Digest
Cache-Status
X-Amz-Replication-Status
X-Varnish-TTL
X-Version
X-Mg-S
X-Fastly-Request-ID
YJS-ID
X-Ismobilevalue
X-Newrelic-App-Data
Public-Key-Pins
X-Correlation-Id
X-HS-Content-Id
X-Accel-Expires
X-HS-Cache-Config
X-Powered-CMS
TP-Cache
X-HS-Hub-Id
AR-CACHE
Fastcgi-Cache
X-MSEdge-Ref
Cache-Tags
X-Cached
X-Ttl
X-Server-Name
X-Cluster-Name
Arr-Disable-Session-Affinity
Realpath
X-Content-Security-Policy-Report-Only
X-Id
X-Daa-Tunnel
Content-MD5
X-HS-Combine-CSS
X-Azure-Ref
X-TTL
X-RateLimit-Remaining
X-Ua-Browser
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cambria-Cache-Control
Payment
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Xrds-Location
X-HS-CF-Cache-Status
X-HS-Prerendered
X-Amz-Apigw-Id
X-Amzn-RequestId
X-GUploader-UploadID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-For
Content-Disposition
X-Px
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Protected-By
X-TEC-API-ROOT
Count-Hit
X-Ratelimit-Remaining
X-Ratelimit-Reset
X-Activity-Id
X-Unique-Id
X-Az
X-AppVersion
X-Page-Id
X-Rid
Cross-Origin-Resource-Policy
X-Logged-In
Cleartype
X-Origin-Server
Accept-Charset
Cross-Origin-Embedder-Policy
X-Git-Hash
X-Proxy
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
X-Microsite
X-Request-Handler-Origin-Region
X-VARITI-CCR
X-Www-Served-By
Version
X-Load-Cache
X-Geo-Country
X-COUNTRY
X-Hits
X-LLID
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Forwarded-Proto
X-Template
X-Varnish-Backend
X-Requestid
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-B3-Sampled
Server-Node
X-PressLabs-Stats
X-App-Server
Healthy
X-Hostname
Server-Name
X-Content-Options
Access-Control-Allow-Method
X-Frontend
X-TT
X-RemovedCookies
X-ProcessESI
Section-Io-Cache
X-B
Viewport
X-Device-Type
X-Request-Guid
X-Varnish-Grace
X-Grace
X-Varnish-Server
Fastly-SIE
X-Fb-Rlafr
Alternate-Protocol
Fastly-SWR
X-Contextid
AKAMAI-GRN
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Cache-Age
DC
X-Status
X-Hl-Ver
X-CSRF-Token
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Yandex-Req-Id
X-Magnolia-Registration
X-Amzn-Remapped-Content-Length
X-Varnish-Ttl
Upgrade-Insecure-Requests
X-App-Version
X-Oracle-Dms-Ecid
MS-Author-Via
Frame-Options
Xet-Cookie
X-Cache-Control
X-EdgeConnect-Cache-Status
TCN
Host
Retry-After
X-CST
X-Origin-CC
X-Origin-TTL
X-SERVER-NAME
X-Type
X-Response-Served-From
X-Original-Request-Id
X-Revision
SD-X-WS
X-Debug
X-AB
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Amp-Access-Control-Allow-Source-Origin
X-ServerID
X-G
X-Mobile
NGB
X-Seen-By
X-Adobe-Content
X-UUID
X-N
X-Adobe-Loc
X-Akamai-Edgescape
X-INCAP-ABP
X-Backend-Name
X-Instance
X-Rendered-As
X-Buckets
X-Cacheable-TTL
X-Debug-IsConnected
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-NYM-Debug-Backend
Cross-Origin-Opener-Policy-Report-Only
X-Lambda-Id
X-Is-Bot
Cache
Access-Control-Request-Headers
Cross-Origin-Embedder-Policy-Report-Only
X-Tumblr-User
X-Akamai-Request-ID2
X-Tumblr-Pixel-1
X-Cache-Status-Check
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Framework
MS-CV
Ms-Operation-Id
X-WP-CF-Super-Cache
X-Mg-Request-UUID
Section-Io-Id
X-WP-CF-Super-Cache-Cache-Control
X-Content-Powered-By
X-RTag
X-Server-W
X-B3-SpanId
X-Trace-Id
X-Tt-Trace-Host
X-RM-Cache-TTL
X-Tt-Trace-Tag
X-Storage
Selected-Fe
Charset
X-ProxyCache-Status
X-Timing-Wait
X-BYPASS-REASON
X-Proxy-Build
X-ProxyCache-Key
YJS-CacheStatus
X-Dc
Paypal-Debug-Id
X-VC-Cache
Webserver
Accept-Language
X-Ms-Version
Onion-Location
Front
X-Ms-Request-Id
Filterid
SRV
X-Vcl-Version
X-Cache-Time
X-User-Agent
Refresh
X-Server-ID
Apigw-Requestid
X-DataDome
X-F-Cache
X-Cache-Hit
X-VC
X-Time
X-Origin-Cache
Liferay-Portal
X-Mly-Id
X-Node-Name
X-Real-IP
Priority
X-Region
X-L-Path
GEO-INFO
X-Webkit-Csp
X-Fastcgi-Cache
X-CLOUD-TRACE-CONTEXT
X-Environment-Context
X-Service
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Mode
X-Hcs-Proxy-Type
X-HTML-Minification-Powered-By
X-Tec-Api-Root
X-LB-Cache
X-Request-Site
X-Tec-Api-Version
X-Rule
X-Origin
X-Optimistic-Header
X-Request-Platform
X-Tec-Api-Origin
X-Request-Bu
X-Rn-Rsrv
X-Tb
X-Drupal-Cache-Tags
X-Rewrite-Enabled
X-SaId
Meta-Geo
X-Api-Version
X-Rocket-Nginx-Serving-Static
X-UPSTREAM-Address
X-VCT
X-HITS
Country
CDN-RequestId
X-JoinUs
X-Tt-Logid
X-IPS-LoggedIn
X-Tcp-Rtt
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Mobile-Only
X-Wix-Request-Id
X-Handled-By
X-Geo-Region
X-Is-Modern-Browser
X-Browser-Name
X-Is-Tablet
X-Adobe-Source
Backend
X-Is-Mobile
X-Provided-By
Mn-Server-Ip
X-Cache-Expired-At
X-Web-Node
X-Datadog-Sampling-Priority
X-Connection-Hash
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Generation-Time
X-Datadog-Trace-Id
X-Pass-Why
Expiry
X-XRDS-Location
X-Platform
Uber-Trace-Id
X-Cms-Context
Url
TWC-Locale-Group
TWC-GeoIP-Country
X-WP-CF-Super-Cache-Active
TWC-Privacy
TWC-Connection-Speed
TWC-GeoIP-City
TWC-GeoIP-DMA
X-Alternate-Cache-Key
TWC-GeoIP-Region
Webcakes-App-Version
Webcakes-App-Name
Web-Mar-Node
X-Cdn-Origin
X-Cache-Action
Fastcgi-Useragent
OT-Force-Account-Verify
TWC-GeoIP-LatLong
X-Cloudmap
Webcakes-Region
Property-Id
X-Shopify-Stage
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Routing-Service
X-RateLimit-Limit-Second
X-Proxy-Cache-Info
X-Detected-As
X-Proxied
X-S
X-Servername
X-Vcache
X-Zipkin-Id
Node
X-Varnish-Beresp-Grace
X-Tncms
TWC-Device-Class
X-Storefront-Renderer-Rendered
X-Origin-Date
X-Origin-Hint
X-Forwarded-Host
X-Httpd
ServerID
X-FB-TRIP-ID
X-Extlb
Cross-Origin-Window-Policy
X-Hit
X-Loop
X-Whom
X-Urbn-Context-Path
X-Tumblr-Pixel-2
X-Urbn-Site-Id
X-Tumblr-Pixel-3
X-Auth-Group-Type
X-Director
X-Cluster
X-Fetched-On
X-App-Environment
X-Format
X-Locale
X-Redis-Cache
X-Cache-Host
X-Hosted-By
X-MP-GENERATED-AT
X-Soup
X-Skip-Cache
X-Logging-Id
X-Cache-Debug
Environment
DB-Nickname
Cache-Hits
Atl-Traceid
Countrycode
Locale
X-CDN-Forward
ServedBy
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Server
X-SayCDN-TTL
X-Endurance-Cache-Level
X-Say-TTL
X-Debug-Info
X-Edge-Location
X-Cluster-Node
X-Say-Cacheable
X-Scope-Id
X-Restarts
Protected
X-Labrador-Cache-Channel
X-PHP-Host
X-FW-Static
AMP-Access-Control-Allow-Source-Origin
X-FW-Type
X-FW-Version
X-Served-From
X-Client-Ip
X-Drupal-Cache-Contexts
X-IPLB-Request-ID
X-IPLB-Instance
Filters
Xserver
WPO-Cache-Status
X-Presslabs-Stats
X-Ua
X-NWS-UUID-VERIFY
X-R9-Blue-Green-Version
Request-ID
LB
X-Varnish-Beresp-Ttl
X-GEO
X-CDN-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
X-No-Session
X-SRCache-Key
X-Sorting-Hat-PodId
X-Varnish-Age
X-ShopId
X-Sorting-Hat-ShopId
X-ShardId
Expect-Staple
X-Generated-By
CloudFront-Viewer-Country
X-Upstream-Ht
X-Upstream-Ct
X-B-Cache
X-Cache-FS-Status
X-Clientip
Mail-Subject
We-Hiring
X-Varnish-Cache-Hits
X-Signature
Cache-Tv-Group
X-Lagoon
X-B3-Traceid
X-Cs
X-Azure-Ref-OriginShield
Referer-Policy
X-FORWARDED-FOR
X-PHP-Backend
X-TA-CDN-Provider
X-Cache-Operation
X-IsAdmin
X-Cache-Rule
X-LSADC-Cache
X-Webstats-RespID
Location
X-Worker
X-SRV
X-Auto-Login
X-Bc-Bl
X-ECache
From-Origin
X-Server-IP
Fl-Custom-Application
X-Site-Version
Cache-Provider
X-UA
Load-Balancing
Candidate-Md5Url
X-Tb-Optimization-Total-Bytes-Saved
DCR-Processing-Time-Ms
Host-ID
S-Rt
Lang
DCR-Decision-By
Origin-Agent-Cluster
MD5-Digest
Source
X-A-Wwc
X-GeoCode
X-GeoCountry
X-Ig-Origin-Region
X-Ig-Push-State
X-External-Request-Id
X-Ec-GeoHdr
X-Destination
X-Developer
X-Ec-Fail
X-Loc
X-ND-Cache
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-ScT
X-S-Cookie
X-Org
X-PERF
X-Rojux
X-D
X-Content-Age
Rendered-Blocks
Sslversion
X-A
X-A-Ccd
Redirect-Candidate
Pragrma
N-Cache
Ngx.Var.Host
Origin
X-A-Dcw
X-A-Dgt
X-Bl-Debug
X-Cache-NE
X-Conf
X-BCube-Filmed-By
X-B-Cookie
X-Aed
X-ApacheServer
X-Application
Meta-Geo-Continent
X-A-Dam
WPO-Cache-Message
Mime-Version
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Accel-Version
X-CACHE-AGE
X-Xfnlog-Site
Store-Cloud-Cache
X-Req
Time-Cloud-Cache
X-Rocket-Build-Number
ServerName
RNT-Time
Server-Host
Vix-Hermes-Req-Id
RNT-Machine
Web-Mar-Region
X-Access
X-Action
X-Aicache-OS
X-PAYTM-SRV-ID
X-Policy
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Save-Cache
X-Section
L5d-Success-Class
Log-Origin
X-Sn-Servicetimems
IsBot
Ha-Gx-Prefs
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Origin-Site
Powered-By
X-GoCache-CacheStatus
X-Sigma
Odigeo-Trace-Id
X-SIPLIST1
X-Sigma-Backend
NM-Fastcgi-Cache
X-AK-Request-ID
X-Origin-Expires
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-Ee-Request-Id
X-Ee-Request-Date
X-Internal-TTL
X-Ee-Generated-By
X-Ee-Origin
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Gamma-Serve
X-Forwarded-Site
X-HS-Content-Campaign-Id
X-From
X-Dispatcher-Server
X-Depends
X-Mvc-Supplant-Cachable
X-CacheTTL
X-CGP
X-Cache-Aspx
X-Bug-Bounty
X-Old-Content-Length
X-Node-Id
X-NMSegId
X-Cms-Device
X-Micro-Cache
X-CUA
X-DefElseHash
X-DefHash
X-Csrf-Jwt
X-Core-Value
X-Contensis-Viewer-Groups
X-Men
X-Up
X-SD-PageType
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
X-Varnish-CookieINHashed-On
Canary
CDN-PullZone
CDN-RequestCountryCode
Cdncip
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-VG-WebCache
X-Via-Fastly
X-URL
Sid
X-VG-TLSProxy
X-Vary-Devices
Apple-News-Services-Handled
X-Varnish-Director
X-Varnish-Hostname
X-Varnish-Remaining-TTL
Cdnsip
Apple-News-Services-Request-Url
Cluster
Country-Code
X-V-Cache
X-Varnish-Authentication
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-NewRelic-App-Data
X-Parent-Response-Time
X-Cached-By
X-VC-TTL
X-NF-Request-ID
X-Cache-Date
X-Vercel-Id
X-Cache-Id
DSUID
X-Viewer-Country
X-Vmg-Version
X-Content-Length
X-Vercel-Cache
X-Level-Front-Cache
X-Thinkindot-L3
X-Mvc-Supplant-OutputCached
X-Thanos
CF-IPCountry
X-App-Name
X-Op-Id-All
X-Amz-Storage-Class
X-Thinkindot-L1
X-B3-Trace-ID
X-Bip
X-Date
X-VarnishDD-TTL
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Block-Status
X-Wikidot-Backend
X-Tx-Id
X-Frame-Option
X-Reqid
X-Render-Time
X-UA-Device-Type
X-Human
X-SB
X-Gdpr
X-HN
X-Gzip
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-Esi-Check
Cmstype
Fastly-Backend-Name
X-Jungle-Id
X-Akamai-Device-Characteristics
X-We-Are-Hiring
X-Debug-Cache-Store
X-Ion-Hop
X-Wikidot-Static-Cache
X-Edge-Server
Cmsid
X-Ec-Custom-Error
X-Ion-Healthy
X-DPWN-IS-SECURE
X-Debug-Cache-Fetch
X-Nyt-Route
X-Sucuri-Cache
L
Cdn-Host
RewriteTestHook
Content-Style-Type
RewriteTeamHook
CDCHOST
X-Request-URI
Tube-Get-Contents
Tube-Got-Eval
CacheControlHeader
Thinkindot-CacheControl-Type
TDXMobile
X-SVT-ORM-VERSION
Req-Svc-Chain
Cdn-Request-Time
Origin-CC
Origin-EX
Click-Count-Error
Cookie
Click-Count-Action-Start
Nord-Request-ID
PFcat
Pics-Label
Machine
Release
Producers
X-Shield-Cache-Expires
Platform
Content-Script-Type
Tube-Got-Results
Thinkindot-CacheControl
X-Pubstack
X-SVT-ORM-RULES
X-Proto
Azure-RegionName
X-Litespeed-Cache-Control
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
Azure-Version
Azure-SiteName
Azure-InstanceId
X-Region-Sid
User-Cache-Control
X-Accel-Expires-Debug
X-Uri
X-AB-Test
V-Age
X-Origin-Time
X-Path
Cache-Contol
Azure-SlotName
X-ZONE
X-Moov-Xdn-Version
Fastly-GeoIP-CountryCode
X-Via-Popn
X-Moov-Xdn-Caching-Status
X-Via-Poph
C-Via
X-Origin-Response-Time
X-Debug-Service
X-ElasticPress-Query
X-Nginx-Cache-Key
X-Via-Popv
X-Proxied-Request
X-Location
X-Datadome
X-Moov-T
Fastly-Drupal-HTML
X-Pad
True-Client-Country-4JS
X-NGINX-Cache
X-HA-Backend
X-Sucuri-ID
Server-Hostname
XM
Server-Ext
Sever-Int
X-Srv
X-AIR-PT
X-Webkit-CSP
X-Varnish-Hits
Show-Do-Not-Sell-Link
NGX
Traceparent
X-Cache-Backend
X-Refresh
X-Ez-Minify-Html
Debug
Server-ID
X-Unity-Cache
X-Air-Pt
X-APP
X-Fastly-Request-Id
X-Fpc
X-Nananana
HostName
X-Servedbyhost
GeoIp-Country-Code
GeoIP-Latitude
X-LB-ID
X-TH-Server
X-DynaTrace-JS-Agent
DataCenter
HA-Ipaddr
Product
WZWS-RAY
Cdn
Tcn
X-Zone
X-VCL-Version
AR-SID
X-AC
X-Amz-Meta-Cb-Modifiedtime
X-B3-Parentspanid
X-Nc
X-Wa
Lb
X-CDN-Provider
X-Nginx-Cache
Fastly-Drupal-Html
SID
X-Newrelic-Synthetics
Xkey-La3
X-Proxy-Cache-La3
X-Proxy-CacheR9
Xkeylog
Serverhost
A
XkeyR9
X-Cache-VC
X-GeoIP
X-Cdn-Forward
X-User
X-Litespeed-Tag
X-TX-ID
X-Vc
X-Datacenter
Edge-Cache
CountryCode
Cs
NtCoent-Length
X-RateLimit-Limit
Resin-Trace
X-Source
X-LB-NoCache
Cdn-Requestid
X-LiteSpeed-Tag
Esi-Enabled
X-Request-Start
X-API-Version
X-LiteSpeed-Cache-Control
X-TT-LOGID
X-Wormhole-Sdk
Akamai-Mon-Iucid-Del
MIME-Version
X-HubSpot-Correlation-Id
X-B3-Spanid
X-NC
X-Aspnet-Version
X-WA
X-Dynatrace-Js-Agent
X-VC-Age
X-ID
X-Service-Response-Time
Sm-Log-Id
CDN
X-Html-Minification-Powered-By
X-Udemy-Cache-App-Namespace
Content-Secure-Policy
X-Scheme
X-TIM-N
X-Styx-Origin-Id
Proxy-Firewall
Pramga
X-Styx-Info
X-HA-Device-Type
X-HA-Bot-Classification
Datacenter
Cr
Wsr-Cache
X-HA-Application-Name
Uri
X-Via-JSL
ServerHost
X-Lsadc-Cache
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Fastly-Backend-Reqs
X-Ez-Minify-Js
X-Lb-Id
RATING
Hostname
X-FPC
Geoip-Latitude
Yjs-Id
X-TimeS
GeoIP-Country-Code
X-Var-Ttl
From-Cache
X-ServedByHost
Server-Id
X-NodeID
X-Stale
X-Pool
X-Request-Host
W
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Oracle-DMS-ECID
X-Aspnetmvc-Version
X-CACHE-KEY
Cloudfront-Viewer-Country
X-NODE
X-MSEdge-Flight
X-App
X-MSEdge-Features
X-Swift-Error
X-Lb-Nocache
X-Akamai-Pragma-Client-IP
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-LAGOON
X-RequestId
X-Shardid
X-Wp-Cf-Super-Cache-Active
X-Shopid
X-Sorting-Hat-Podid
X-Ramcache
X-ByteArk-Cache
X-Correlation-ID
X-DynaTrace
X-ByteArk-ReqID
X-Proxy-Cache-LA2
X-Vgn-Hpd-Reason
Ohc-Cache-HIT
X-Key
X-Cache-Grace
X-VServer
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
Ohc-File-Size
Surrogated-Key
T-Server
Srv
X-CS
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Varnish-Beresp-TTL
X-Elasticpress-Query
Yak-Timeinfo
X-DataCenter
Cl-Cache
X-Cdn-Cache-Status
Ngx
X-Geo
X-CSRF-TOKEN
X-PageType
X-Sucuri-Id
X-Web-Server
Req-ID
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Via-CDN
X-Jobs
X-ATG-Version
Akamai-X-True-TTL
WebServer
X-DC
X-Ha-Backend
X-Th-Server
N1-Cache
X-Iplb-Instance
X-Iplb-Request-Id
X-Beacon
Warning
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Limited
X-MiniProfiler-Ids
My-App
X-Check-Cacheable
X-Env
Host-Name
X-Mg-Cache
X-Zen-Fury
X-Geolocation
User-Agent
X-Request-Url
X-Fastly-Cache-Status
Xkey-G-Jp